3 +--------------------------------------------------------------------+
4 | CiviCRM version 4.6 |
5 +--------------------------------------------------------------------+
6 | Copyright CiviCRM LLC (c) 2004-2015 |
7 +--------------------------------------------------------------------+
8 | This file is a part of CiviCRM. |
10 | CiviCRM is free software; you can copy, modify, and distribute it |
11 | under the terms of the GNU Affero General Public License |
12 | Version 3, 19 November 2007 and the CiviCRM Licensing Exception. |
14 | CiviCRM is distributed in the hope that it will be useful, but |
15 | WITHOUT ANY WARRANTY; without even the implied warranty of |
16 | MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. |
17 | See the GNU Affero General Public License for more details. |
19 | You should have received a copy of the GNU Affero General Public |
20 | License and the CiviCRM Licensing Exception along |
21 | with this program; if not, contact CiviCRM LLC |
22 | at info[AT]civicrm[DOT]org. If you have questions about the |
23 | GNU Affero General Public License or the licensing of CiviCRM, |
24 | see the CiviCRM license FAQ at http://civicrm.org/licensing |
25 +--------------------------------------------------------------------+
31 * @copyright CiviCRM LLC (c) 2004-2015
38 * The various type of permissions.
50 * Given a permission string, check for access requirements
53 * The permission to check.
54 * @param int $contactID
55 * The contactID for whom the check is made.
58 * true if yes, else false
60 public static function check($str, $contactID = NULL) {
61 if ($contactID == NULL) {
62 $session = CRM_Core_Session
::singleton();
63 $contactID = $session->get('userID');
71 return CRM_ACL_BAO_ACL
::check($str, $contactID);
75 * Get the permissioned where clause for the user.
78 * The type of permission needed.
79 * @param array $tables
80 * (reference ) add the tables that are needed for the select clause.
81 * @param array $whereTables
82 * (reference ) add the tables that are needed for the where clause.
83 * @param int $contactID
84 * The contactID for whom the check is made.
85 * @param bool $onlyDeleted
86 * Whether to include only deleted contacts.
87 * @param bool $skipDeleteClause
88 * Don't add delete clause if this is true,.
89 * this means it is handled by generating query
92 * the group where clause for this user
94 public static function whereClause(
100 $skipDeleteClause = FALSE
102 // the default value which is valid for rhe final AND
103 $deleteClause = ' ( 1 ) ';
104 if (!$skipDeleteClause) {
105 if (CRM_Core_Permission
::check('access deleted contacts') and $onlyDeleted) {
106 $deleteClause = '(contact_a.is_deleted)';
110 $deleteClause = '(contact_a.is_deleted = 0)';
114 // first see if the contact has edit / view all contacts
115 if (CRM_Core_Permission
::check('edit all contacts') ||
116 ($type == self
::VIEW
&&
117 CRM_Core_Permission
::check('view all contacts')
120 return $skipDeleteClause ?
' ( 1 ) ' : $deleteClause;
123 if ($contactID == NULL) {
124 $session = CRM_Core_Session
::singleton();
125 $contactID = $session->get('userID');
133 return implode(' AND ',
135 CRM_ACL_BAO_ACL
::whereClause($type,
146 * Get all the groups the user has access to for the given operation.
149 * The type of permission needed.
150 * @param int $contactID
151 * The contactID for whom the check is made.
153 * @param string $tableName
154 * @param null $allGroups
155 * @param null $includedGroups
158 * the ids of the groups for which the user has permissions
160 public static function group(
163 $tableName = 'civicrm_saved_search',
165 $includedGroups = NULL
167 if ($contactID == NULL) {
168 $session = CRM_Core_Session
::singleton();
169 $contactID = $session->get('userID');
177 return CRM_ACL_BAO_ACL
::group($type, $contactID, $tableName, $allGroups, $includedGroups);
181 * Check if the user has access to this group for operation $type
184 * The type of permission needed.
185 * @param int $groupID
186 * @param int $contactID
187 * The contactID for whom the check is made.
188 * @param string $tableName
189 * @param null $allGroups
190 * @param null $includedGroups
194 * the ids of the groups for which the user has permissions
196 public static function groupPermission(
200 $tableName = 'civicrm_saved_search',
202 $includedGroups = NULL,
206 static $cache = array();
208 //@todo this is pretty hacky!!!
209 //adding a way for unit tests to flush the cache
215 $session = CRM_Core_Session
::singleton();
217 if ($session->get('userID')) {
218 $contactID = $session->get('userID');
222 $key = "{$tableName}_{$type}_{$contactID}";
223 if (array_key_exists($key, $cache)) {
224 $groups = &$cache[$key];
227 $groups = self
::group($type, $contactID, $tableName, $allGroups, $includedGroups);
228 $cache[$key] = $groups;
230 if (empty($groups)) {
234 return in_array($groupID, $groups) ?
TRUE : FALSE;